summaryrefslogtreecommitdiffstats
path: root/jail
diff options
context:
space:
mode:
authorEtienne CHAMPETIER <champetier.etienne@gmail.com>2015-10-08 22:01:44 +0200
committerJohn Crispin <blogic@openwrt.org>2015-10-08 18:19:02 +0200
commitef490722885a5c708c70dff656d094c7043ae081 (patch)
tree0f4a49028b2772177d51ab0dfa4094c4739081ca /jail
parent25b58f2d549c0fb67e33849c2fc14106f667f404 (diff)
downloadunitd-ef490722885a5c708c70dff656d094c7043ae081.tar
unitd-ef490722885a5c708c70dff656d094c7043ae081.zip
jail: Add MS_NODEV MS_NOEXEC MS_NOSUID mount options where needed
this completes fafbf7338ec8304f2a0ec0ba76048fba2c01c07e Signed-off-by: Etienne CHAMPETIER <champetier.etienne@gmail.com>
Diffstat (limited to 'jail')
-rw-r--r--jail/jail.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/jail/jail.c b/jail/jail.c
index f459a5e..56dc9ca 100644
--- a/jail/jail.c
+++ b/jail/jail.c
@@ -193,11 +193,11 @@ static int build_jail_fs()
rmdir("/old");
if (opts.procfs) {
mkdir("/proc", 0755);
- mount("proc", "/proc", "proc", MS_NOATIME, 0);
+ mount("proc", "/proc", "proc", MS_NOATIME | MS_NODEV | MS_NOEXEC | MS_NOSUID, 0);
}
if (opts.sysfs) {
mkdir("/sys", 0755);
- mount("sysfs", "/sys", "sysfs", MS_NOATIME, 0);
+ mount("sysfs", "/sys", "sysfs", MS_NOATIME | MS_NODEV | MS_NOEXEC | MS_NOSUID, 0);
}
if (opts.ronly)
mount(NULL, "/", NULL, MS_RDONLY | MS_REMOUNT, 0);